Create New User Whilst Logged On
None
Vulnerability Details
The website www.teavana.com allows users already logged on to create new account with a very simple url redirect. When an account is created a page is displayed with your account information and what you want to update. By simply refreshing the page allows you to create a new account whilst still logged on. If you try to recreate the same account with the same email but different password, there will be no error message displayed though when you try to login, the password will be incorrect.
Actions
View on HackerOneReport Stats
- Report ID: 193478
- State: Closed
- Substate: not-applicable
- Upvotes: 4